10 Sep 2026 · 4 min read

Agentic Advertising and Data Protection: What Changes

TL;DR: Agentic advertising does not introduce new data protection obligations, but it changes the accountability chain for meeting existing ones. When an agent negotiates a deal that uses personal data, the question of who made the data processing decision becomes more complex. The buyer remains the data controller; the mandate is the document that connects the buyer's data processing intent to the agent's operational decisions; and the DealSheet is the record that evidences what data was used and on what basis.

Data protection law in the UK and EU operates on a controller-processor model. The data controller determines the purposes and means of processing personal data; the processor processes it on the controller's instructions. In programmatic advertising, the advertiser is typically the controller for their own campaign audiences; the DSP and the ad tech stack are processors acting on the advertiser's instructions.

Agentic advertising does not change this model, but it adds a layer of delegation that the controller must be prepared to account for. When a buy-side agent negotiates a deal that uses audience data, the agent is acting on behalf of the controller. The controller remains liable for ensuring that the data use complies with their legal basis, regardless of whether the decision was made by a human trader or an AI agent.

What the mandate must address

The mandate document is the mechanism through which the data controller exercises their responsibilities in an agentic context. It should specify:

Which audience data the agent is authorised to use. This means specific first-party segment IDs, named third-party data providers, and the legal basis under which each is processed. Audience parameters that say "use contextual targeting and retargeting" are insufficient: the mandate should name the data sources and confirm the legal basis for each.

What data the agent may accept from the sell side. In bilateral negotiation, the sell-side agent may offer publisher audience data as part of a deal proposal. If the buyer's agent accepts this data for use in the deal, the buyer may become a joint controller for that data. The mandate should define whether the agent is permitted to accept sell-side data, under what conditions, and what consent or legitimate interest basis applies.

What the agent must not use. The exclusion list in the mandate is as important as the inclusion list. Special category data (health, political opinion, religion) has a higher processing threshold under UK GDPR and EU GDPR. The mandate should explicitly prohibit the agent from using audience data that could constitute special category data unless the buyer has confirmed the legal basis for doing so.

How the DealSheet supports compliance

The DealSheet provides an auditable record of which audience data was used in each deal. For data protection purposes, this is significant: it connects the buyer's legal basis documentation to the specific deals that were executed under that basis.

In a conventional impression log, the audience data used in a transaction may not be recoverable at the individual deal level: it was part of the targeting configuration, not a per-transaction record. In a bilateral DealSheet, the audience parameters agreed in the deal are part of the deal record. A data protection audit or a subject access request response that requires the buyer to evidence what data was used when can draw on the DealSheet archive rather than relying on a system configuration that may have changed since the campaign ran.

This is an advantage of the DealSheet model for compliance purposes, but it also raises the standard: if the DealSheet contains audience parameter data and the buyer's records are audited, the audience data evidenced in the DealSheet must be consistent with the buyer's legal basis documentation. Inconsistencies between the two are an audit finding.

Practical steps for buyers

Before deploying a buy-side agent that uses personal data, the buyer should ensure that:

Their Records of Processing Activity (RoPA) includes agentic advertising as a processing activity, with the agent identified as a processor and the data types, legal bases, and retention periods specified.

Their Data Protection Impact Assessment covers agentic advertising if the campaign involves profiling, systematic processing of personal data, or data at scale.

Their mandate document has been reviewed for data protection compliance, not only for campaign operational parameters.

Their contracts with the agentic marketplace and with any data providers used in the mandate have been reviewed to confirm processor status and data processing agreement requirements.

None of these steps are unique to agentic advertising: they are standard data protection practice for any programmatic campaign using personal data. The difference in an agentic context is that the accountability trail runs through the mandate and the DealSheet, and both should be designed with compliance documentation in mind from the outset.

All articles

Speak to the team